Amazon

Monday, 15 June 2015

Will Kinghan New Doc henryhowardfinance.co.uk

 Will Kinghan New Doc henryhowardfinance.co.uk New doc.doc macro malware.

These emails aren't from these companies at all , they are just being used to make the email look more genuine, ie. from a real company.
Note
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Header:

From: Will Kinghan {WKinghan@hhf.uk.com}
Subject: New Doc

Message Body:
Hello,

My apologies again.

Document attached

Will

With kind regards,

Will Kinghan
Account Manager
T: 01633 415235 |M: 07468723790| E: wkinghan@hhf.uk.com

www.henryhowardfinance.co.uk

Head Office

T
: 01633 415222  | F: 01633 415223
Unit 5
| Langstone Business Village | Langstone Park | Langstone | Newport | Gwent | NP18 2LH   

 Attachment:
New doc.doc
Sha256 Hashes:
163298d1e1657833db1c591fba424d9a1e26f894e957b9810f150a0e95991dcd [1]
412a6c4ec8d4adbc9418f9857d13e3513771a731241eb16b46dce8d40311ce41 [2]
4b8a883a69576f6b80e1b304c462ee027b57dfa379f53ab7611d11f743e699cf [3]

Malware Virus Scanner Reports:
VirusTotal Report: [1] (detection 3/57)
VirusTotal Report: [2] (detection 3/57)
VirusTotal Report: [3] (detection 3/57)

NOTE

The current round of Word/Excel/XML attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to

steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))

Cheers,
Steve

[Nyfast] Payment accepted 101153.doc

[Nyfast] Payment accepted 101153.doc macro malware.

These emails aren't from these companies at all , they are just being used to make the email look more genuine, ie. from a real company.
Note
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Header:

Subject: [Nyfast] Payment accepted
From: Nyfast {sales@nyfast.com}

Message Body:
Hi ,
Thank you for shopping with Nyfast!
 
Order ZUJIEQGQV - Payment processed
Your payment for order with the reference ZUJIEQGQV was successfully processed.
 
You can review your order and download your invoice from the "Order history" section of your customer account by clicking "My account" on our shop.
If you have a guest account, you can follow your order via the "Guest Tracking" section on our shop.

 Attachment:
101153.doc
Sha256 Hashes:
163298d1e1657833db1c591fba424d9a1e26f894e957b9810f150a0e95991dcd [1]
412a6c4ec8d4adbc9418f9857d13e3513771a731241eb16b46dce8d40311ce41 [2]
4b8a883a69576f6b80e1b304c462ee027b57dfa379f53ab7611d11f743e699cf [3]

Malware Virus Scanner Reports:
VirusTotal Report: [1] (detection 3/57)
VirusTotal Report: [2] (detection 3/57)
VirusTotal Report: [3] (detection 3/57)

NOTE

The current round of Word/Excel/XML attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to

steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))

Cheers,
Steve

Wednesday, 10 June 2015

Your monthly BTT telephone bill Hayley Sweeney admins@bttcomms.com

Your monthly BTT telephone bill Hayley Sweeney admins@bttcomms.com Invoice_68362.doc macro malware.

These emails aren't from these companies at all , they are just being used to make the email look more genuine, ie. from a real company.
Note
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Header:

From: Hayley Sweeney {admins@bttcomms.com}
Subject: Your monthly BTT telephone bill

Message Body:
Please find attached your telephone bill for last month.
This message was sent automatically.
For any queries relating to this bill, please contact Customer Services on 01536 211100.

 Attachment:
Invoice_68362.doc
Sha256 Hashes:
bba2cce71f9c253a34dae8887effeff97874ee3a941f2fa42015aea04f581168 [1]
cd88f730db594ce26d2a82d93f7511828b9d07cfc1bc53c5711f430064cccdcf [2]
eff01d391b8f2a2f7a2d661a112e0bc47835188a9dc963fbc8e1c2d77a59bc61 [3]
f09f4e090cd8bab6b430ade5be9b38047e525e66f578370edcc44ef25ef8f2b1 [4]
fd4a7d139d44b20825fe2b74f64f2656fb8d14aab618b65b62705dbd1c43876d [5]

Malware Virus Scanner Reports:
VirusTotal Report: [1] (detection 5/57)
VirusTotal Report: [2] (detection 5/57)
VirusTotal Report: [3] (detection 5/57)
VirusTotal Report: [4] (detection 5/57)
VirusTotal Report: [5] (detection 5/57)


NOTE

The current round of Word/Excel/XML attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to

steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))

Cheers,
Steve

Tuesday, 9 June 2015

steve.tasker Password Confirmation thomashiggins.com

steve.tasker Password Confirmation thomashiggins.com 1913.doc macro malware.

These emails aren't from these companies at all , they are just being used to make the email look more genuine, ie. from a real company.
Note
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Header:

From: steve.tasker785@thomashiggins.com
Subject: Password Confirmation  [261897707725] T82

Message Body:
Full document is attached

 Attachment:
1913.doc
Sha256 Hashes:
a6e1043afe619b02cf4fb43c460bf1827010d03a2010571d1e4b2f5ee66a6825 [1]
bbb3958f20991520cac5f52e57befc3b9527ad6a7829cbd1e3ccabe5d2f66369 [2]
9dc725615952bb0601fc957a3b05428d9407bdaaebefaaea78e9f46c6592e9e3 [3]
9c453a02704170948a0842a446fb247bd1e7e1d71414552f31e64982db91e7b1 [4]
4f765fb551e2dfd99fa5b10f78363ca63b579132b094981aaab609880f6cc676 [5]

Malware Virus Scanner Reports:
VirusTotal Report: [1] (detection 2/57)
VirusTotal Report: [2] (detection 2/57)
VirusTotal Report: [3] (detection 2/57)
VirusTotal Report: [4] (detection 2/57)
VirusTotal Report: [5] (detection 2/57)


NOTE

The current round of Word/Excel/XML attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to

steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))

Cheers,
Steve

Monday, 8 June 2015

Bank payment sarah@hairandhealth.co.uk

Bank payment sarah@hairandhealth.co.uk Bank payment 100615.pdf macro malware.

These emails aren't from these companies at all , they are just being used to make the email look more genuine, ie. from a real company.
Note
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Header:

From: sarah@hairandhealth.co.uk
Subject: Bank payment

Message Body:
Dear client

Please find attached a bank payment for £3625.10 dated 10th June 2015 
to pay invoice 1757.  With thanks.

Kind regards

Sarah
Accounts

 Attachment:
Bank payment 100615.pdf
Sha256 Hashes:
48708920689898e49b95fa8716072cfa8dde65063b3455c0fbd3d1973efa8000 [1]
80410f74dca5ffae069fa4a07c368e749f351ffe385432ab816b64024697a06e [2]
837665851dbf56847df9c1632ee725e793f75a2018fc3793f825666b81bb06db [3]
a2492880d31105a93dc9f04db62a724c268daa926fa1aa23dcf7e7969c40da8d [4]
f4e26d1d100e2f1d0fc0a91cec4c280ab69b536e69340be39253c7c4db9ca8de [5]

Malware Virus Scanner Reports:
VirusTotal Report: [1] (detection 2/57)
VirusTotal Report: [2] (detection 2/57)
VirusTotal Report: [3] (detection 2/57)
VirusTotal Report: [4] (detection 2/57)
VirusTotal Report: [5] (detection 2/57)

Hybrid Analysis Report: [3]

Malwr Report: [3]

NOTE

The current round of Word/Excel/XML attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to

steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))

Cheers,
Steve